Legal
Version 1.2 · Effective 29 September 2026 · Corvair Pte. Ltd. (UEN 202551453H)
IPGuru is operated by Corvair Pte. Ltd., a company incorporated in Singapore (UEN 202551453H), whose registered office is at 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216. In these terms, "we", "us" and "our" mean Corvair Pte. Ltd. "You" and "your" mean the person or organisation using the service.
Accepting these terms. You accept these terms by ticking the box or clicking to agree when you sign up or buy. That electronic acceptance binds you as a signature would, and we keep a record of it. If you accept for an organisation, you confirm that you have authority to bind it, and "you" includes that organisation.
These terms are a contract between you and us. They apply whichever of our storefronts you arrived through. ipguru.ai and invent.sg are brands of the same company, not separate businesses, and the seller is the same in every case.
These terms incorporate our Acceptable Use Policy, our Refund Policy and our Privacy Policy. Together they are the whole agreement between us about the service. If you take part through a school, university, employer, event organiser or other institution, its own terms may also apply to your participation (clause 5.1).
IPGuru is a single service, built and operated from Singapore. A storefront such as invent.sg is a branded surface onto that same service, with its own language, currency and price list. It is not a different product and not a different company.
So there is one set of terms, these, and a Market Schedule for your market carrying only local particulars and any local law that must apply. Schedule 1 is the register of them, and the schedule for your market is published alongside these terms.
How the two fit together, which is the only rule you need:
These terms govern. Your Market Schedule prevails only where it states something the law of your market requires, and then only as far as that law requires. Where the two differ in any other way, you are entitled to whichever is more favourable to you.
That rule exists so a market schedule can add local protections and can never quietly take a protection away. If a schedule ever appears to reduce a right you have under these terms, these terms apply instead.
What a Market Schedule can never change, in any market: who the seller is, what the service does, clause 4 on artificial intelligence, clause 6 on ownership of your material and how we may use it, clause 7 on confidentiality, or our position on using your content to train models. Those are the same for every customer everywhere, and changing any of them is a change to this document that reaches every market at once.
A note on how we have written this. We have tried to write a contract you can actually read. Where a clause matters to you, we have explained why rather than hiding it in defined terms. Where we limit our responsibility, we have said so plainly rather than burying it. If any part of this document is unclear, tell us and we will fix the wording.
IPGuru is a software service that helps you explore an idea, develop it, and prepare to act on it. You can start from almost anything: an idea, a problem, a goal or challenge, an existing product or process, a hypothesis, a document, or your own experience. The service helps you:
Which tools and documents are open to you depends on your membership level and any project grade you hold, as published on our pricing pages when you buy. The service changes over time (clause 14). Everything it produces is output under clause 4: a working draft for you to review, decide on and act on.
IPGuru is not a professional adviser. We are not a law firm, a patent attorney or agent, a healthcare provider, or a financial, investment, tax or regulatory adviser, and we do not give legal, medical, financial, investment, tax or regulatory advice. No attorney-client, doctor-patient, fiduciary or advisory relationship arises from your use of the service.
Health and medical inventions are welcome. The service can help you develop and protect inventions in health, medicine and the life sciences, such as devices, diagnostics, therapies and digital health tools. It is not for clinical use. It is not a medical device, it does not diagnose, treat, monitor or advise on the health of any person, it gives no medical advice, and it is not part of any treatment, care or clinical programme. Do not use the service, or anything it produces, to make a decision about the health or care of any person.
No patient data. Do not upload identifiable health information about a patient or any other person, such as medical records, clinical notes, test results or images that identify someone, including protected health information under the US HIPAA rules. Use anonymised or synthetic data instead. If you mention your own health to explain an invention, keep it to what the invention needs. We are not a healthcare provider, health plan or healthcare clearinghouse, or a business associate of one, we do not sign business associate agreements, and we do not hold health records for anyone.
We do not:
You are responsible for your filings, for the deadlines that apply to them, and for engaging a qualified patent attorney or agent in each jurisdiction where you seek protection. You are equally responsible for what you do with anything else the service produces, including raising funds, running a campaign, publishing, licensing, applying for a grant or entering a competition. Where a decision has legal, financial or regulatory consequences, take advice from a qualified professional. Nothing the service produces removes that responsibility.
These limits are real and they are the reason this section is not buried at the end.
We cannot guarantee that a patent will be granted. Only a patent office decides that. A well-prepared application improves your prospects; it does not assure any outcome.
We cannot guarantee patentability. We cannot guarantee that your invention is new, novel, inventive, non-obvious, or capable of protection in any jurisdiction.
Prior art search is not exhaustive. Our searches run across a large collection of published patents and other sources, but no search covers everything that has ever been made public anywhere in any language. We cannot guarantee that no relevant prior art exists, and the absence of a result is not evidence of absence.
Assessments are best-effort. State-of-the-art, market, competitive and commercial assessments are informed input for your own judgment. We do not guarantee they are accurate, current or complete, and you should not treat any of them as the final word.
We cannot promise a commercial outcome. A business plan, pitch, crowdfunding plan, grant outline, licensing brief or competition entry prepared with the service does not assure funding, backers, sales, a licence, an award or any return. Projections, market sizes and prices in them are estimates.
We are not scientists. We cannot verify, test, reproduce or vouch for any scientific or technical claim, dataset or experimental result in your invention.
We are not clinicians. We cannot assess or vouch for the safety or effectiveness of any medical, pharmaceutical or health invention, and nothing the service produces is evidence of either. Clinical testing, ethics approval and regulatory clearance are for you and the proper authorities.
Simulations are models. Where the service simulates how an invention might behave, the result is a model built on assumptions. It is not a test, a certification or evidence that a design works or is safe. Build and test prototypes safely, and follow the law and the instructions for any tools, materials or services you use.
Software patents. You can use the service for any idea, including software, but it is not built to prepare software patent applications, and many patent offices restrict them.
Publication destroys novelty. If you disclose your invention publicly before filing, you may lose the ability to protect it in most countries. A crowdfunding page, a pitch made in public, a competition or science-fair entry and an open-source release can all be public disclosures. The service includes sharing and publication features. Using them is your decision and we cannot reverse the consequences. See clause 12.
Much of what the service produces is generated by artificial intelligence models, including models operated by third parties on our behalf. This clause explains what that means for you, because a contract for this product that did not address it would not be worth much.
Output may be wrong. AI models can produce text that is inaccurate, incomplete, internally inconsistent, out of date, or entirely fabricated while appearing confident and well-sourced. This includes citations, references to prior art, statements of law, technical assertions and numerical claims.
Output must be reviewed before you rely on it. Every draft the service produces is a draft. You must have any document you intend to file reviewed by a qualified patent attorney or agent before filing it, and you must satisfy yourself that any factual or technical assertion in it is correct.
Output may not be unique. Given similar inputs, the models may produce similar output for different users. We do not warrant that any output is original, and generating output does not by itself create any intellectual property right in it.
Grounding is not verification. Where the service cites your project's own research, that citation shows the basis on which the output was produced. It is not an independent verification that the underlying source is accurate or that the output correctly represents it.
Safety systems. Requests, uploads and outputs, including generated images and video, pass through layered safety systems: the safety guardrails built into the AI models we use; Google Cloud Model Armor, which screens prompts and responses for unsafe content; Google Cloud Armor, which screens traffic at the edge of our network and blocks abusive or malicious requests; and our own filters, prompts and checks. Together they catch, block or redirect requests for prohibited or restricted content. They can be wrong in either direction. If you think a refusal is mistaken, raise it with support.
Third-party model providers. We use third-party AI model providers to deliver the service. They process your content as our sub-processors under written terms, and they are listed in our Privacy Policy.
Decision models, including Jev. We are introducing Jev, a decision model provided by TypeSafe AI, Inc., for some of the scoring, grading, ranking and classification the service performs. Jev does not write text. It returns a fixed answer, such as a score or a category, with a probability attached. A score or grade produced this way is output under this clause: it may be wrong, it must be reviewed before you rely on it, and it is not a professional opinion or a decision about your legal rights. TypeSafe processes content as our sub-processor under written terms that do not permit it to train models on your content without our consent, which we do not give. It is listed in our Privacy Policy.
We do not use Your Content to train AI models. Your Content is not used to train, fine-tune or improve any AI model, ours or anyone else's. We contract with our model providers on terms that prohibit it. We use Telemetry (Schedule 3), which contains none of Your Content, to run, secure and improve the service, as described in our Privacy Policy. We also analyse chat and generation histories by automated means to improve the service's own software, under the rules in clause 6. That improves prompts, rubrics, filters and similar parts of the service. It is not model training.
Minimum age. You must be at least fifteen years old to create an account yourself. A storefront serving a particular market may set a higher minimum, and where it does, that higher minimum applies to you. We never set a lower one for an account you create yourself. Younger users can take part only with the permission of a parent or guardian, or through an institution, under clause 5.2.
Accuracy. Keep the information on your account accurate, and keep your credentials secure. You are responsible for activity under your account except to the extent it results from our failure. Tell us at once at support@ipguru.ai if you think your account, a token or a connection has been compromised.
One account per person. Accounts are personal to you. Do not share credentials. If you need several people to work on a project, invite them to the project rather than sharing a login.
Connected apps and access tokens. You can use the service from another application, such as an AI assistant, through our connector, which uses the Model Context Protocol (MCP), or with a personal access token. Everything done through a connected app or a token is use of the service under these terms, the Acceptable Use Policy and the Privacy Policy, in the same way as use in our own app, and it is activity on your account. You choose which apps to connect and what each may do, and you can revoke any connection or token at any time. Keep each token secret. You are responsible for what a connected app does with the access you give it. When a connected app takes content from the service, that app's own terms and privacy notice govern what it does with it, and our confidentiality obligation in clause 7 does not extend to that app. We may suspend a connection or token that is used in breach of these terms or puts the service at risk, and we will tell you why.
A school, university, training provider, government agency or programme, employer, event or competition organiser, or other organisation (an institution) can provide the service to its students, staff, members or participants. There are four ways it can do this, and they can be combined:
Accounts you hold yourself. If you created your account yourself, it stays yours even if an institution pays for your membership or you join its cohort. Nothing you create outside a cohort or deployment is shared with the institution unless you choose to share it.
The institution's own terms. An institution may have its own terms, policies or agreements that you must accept to take part, such as a code of conduct, an academic integrity policy, competition or event rules, an employment or IT policy, or a licence agreement. They are shown to you before you join, and they govern your relationship with the institution. These terms still govern your relationship with us, subject to anything the agreement for a dedicated platform says about how it is run. Neither an institution's terms nor that agreement can reduce what we promise you in clause 4 (artificial intelligence), clause 7 (confidentiality, apart from the access described below) or our position on training models.
Ownership is between you and the institution. As between you and us, Your Content is yours (clause 6), and taking part through an institution does not give it any ownership under these terms. Whether an institution, such as your employer, has rights in what you create, under an employment contract, an invention assignment, an intellectual property policy, competition or event rules, or the law, is a matter between you and it. The same applies to judging, prizes and publicity at an event. We do not decide those questions, advise on them or take part in disputes about them (clause 6).
What an institution gives you. A cohort or deployment may give you a membership, a project grade or other features for a set period, paid for by the institution. What it gives, and for how long, is shown before you join. Access paid for by an institution is not a purchase by you: the merchant of record is not involved unless the institution's agreement with us says so, and the Refund Policy does not apply to it. When the period ends, your account returns to whatever you hold yourself. Nothing is deleted, and clause 10 describes what happens to capabilities that needed paid access.
What the institution can see. In a cohort, the instructor and others the institution names, such as teaching assistants or assessors, may have read-only access to the brainstorms, projects and material, generated or uploaded, that belong to the class. In a hackathon, competition or other event, the organiser and the judges and mentors it names may have read-only access to the entries and material that belong to the event. In a workplace deployment, the organisation's reviewers see what its terms say, such as the ideas you submit to its programme. The terms shown before you join say what is visible, and the institution may make that visibility a condition of taking part. You can share more if you choose. Reviewers cannot change your work, and cannot see anything outside the cohort or deployment unless you share it. Their access is recorded and appears in your activity log.
When a class or event ends. At the end of a cohort, you review the access of the instructor, organiser, judges and mentors, and anything shared through the cohort. Unless you choose to keep them, they end. Your own work is not affected.
Leaving. You can leave a cohort at any time. Leaving ends the instructor's access and what the cohort gave you. What leaving means for your course is a matter for your institution. If a school, university, training provider or event organiser created your account, or you use its licensed deployment, you can move your work to an account of your own, or export it, when your place with it ends. If you are too young to hold an account yourself, you or your parent or guardian can export it. In a workplace deployment, what happens to your work when you leave the organisation is decided by the organisation's own rules, and we follow its instructions.
Your personal data. In a cohort, a workplace or licensed deployment, or a dedicated platform, the institution may be the controller of some of your personal data, with us processing it on its behalf. The Privacy Policy explains how this works.
Age and permission.
Schools and government programmes. A school, education authority or government programme may use the service with students under the age of majority, including students younger than the minimum age in clause 5. It can do this only under a written agreement with us that sets the age range and the way consent is given. The institution is responsible for obtaining and recording any consent the law requires, and for telling parents and guardians how the service is used.
Parents and guardians. A parent or guardian can ask us, directly or through the institution, to see, correct, export or delete their child's data, to opt the child in to or out of the analytics in clause 6, or to withdraw consent. Withdrawing consent ends the child's use of the service.
Protections that always apply. An account held by someone under the age of majority has these protections:
You own your material. You keep all rights in what you upload. To the extent we have any rights in the outputs the service generates for you, we assign them to you. Material owned by others that appears in an output, such as a cited patent or article, stays its owner's. We claim no ownership of your invention, your documents, your data or your ideas.
Inventors and collaborators. Patent offices generally require a human inventor, and output generated by AI may not be protectable on its own. You are responsible for naming the right inventors. When several people work on a project, who owns what between them is for them to agree; in the service, the project owner controls the project.
Ownership disputes. Who owns an idea or invention, as between you and an employer, a school, a client, a collaborator or anyone else, is for you and them. We do not decide it, advise on it or take part in disputes about it. If we are told of a dispute, we follow the instructions of whoever controls the account or project under these terms, and any court order.
The licence you give us, and its limits. You grant us a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, display and process your material to provide, secure and support the service to you, and to improve the service as described below. This licence exists so that we can run and improve the software. It does not permit us to use your material for any other purpose, and it ends when your material is deleted, subject to clause 16.
We do not use your material to market to others, to train models (clause 4), or to develop products other than by improving the service as described below.
How we improve the service. We may run automated analytics over chat and generation histories, meaning your conversations with the service and the outputs it generates for you. We do this to find where the service falls short and to keep improving its filters, safety guardrails, prompts, templates, instructions, guidelines, rubrics, policies and other internal software capabilities. Three rules apply:
Your responsibility for what you upload. You confirm that you have the rights necessary to upload and process the material you provide, and that doing so does not infringe anyone else's rights or breach any obligation of confidence you owe.
Our material. The service itself, including its software, method, prompts, models, interfaces, templates and documentation, remains ours. We grant you a personal, non-exclusive, non-transferable, revocable licence to use the service in accordance with these terms, for the term of your access.
What you may not do with the service. You may not copy, modify, reverse engineer, decompile or attempt to derive the source of the service; resell, sublicense or provide it as a service to others; use it to build a competing product; scrape, harvest or systematically extract data from it; use automated means to access it other than through an interface we provide; or remove any watermark, notice or attribution.
Free-tier output. Deliverables produced on a free account carry an IPGuru.ai watermark. You may use those deliverables for your own purposes, including sharing them with an attorney, but you may not remove or obscure the watermark. Upgrading a project removes it from subsequent deliverables.
Feedback. If you send us suggestions or feedback about the service, we may use them freely and without payment to you. This does not cover Your Content.
Publicity. We will not use your name, logo, project or words in our marketing without your written consent.
This clause matters more than any other in this document for most of our customers, so it stands on its own.
Your project is private by default. A project's knowledge base, memory and vault are private to you and to anyone you deliberately invite, including an instructor or reviewer through a cohort or deployment you join (clause 5.1). Nothing is public unless you make it public.
When our staff can see your content. Our support team's normal view is the shape of your account, meaning your projects, entitlements, permissions, status and activity, not their contents. There is no standing access. Our staff can see Your Content only:
Every access is recorded. Access under 1 and 5 always appears in your activity log. Access under 2 to 4 appears there unless telling you would create a risk of harm, prejudice an investigation or is prohibited by law.
Safety review. Automated systems check requests, uploads and outputs for the uses the Acceptable Use Policy prohibits. Where they flag weapons development or a serious risk of harm, such as work towards a biological, chemical, radiological or nuclear weapon, material that sexualises or abuses a child, or a credible threat to someone's life, a trained member of our team may review what was flagged, and it may lead to an investigation under clause 15. The review is limited to what was flagged and is recorded. It appears in your activity log unless telling you would create a risk of harm or is prohibited by law.
Uploads are scanned. Files you upload are scanned for malware and prohibited content, including sexual content and material that sexualises or abuses a child, before they enter your knowledge base. Items that fail are quarantined and do not enter it.
Our confidentiality obligation. We will keep Your Content confidential and use it only as clause 6 permits. We disclose it only:
This obligation survives the end of this agreement.
What confidentiality cannot do. Confidentiality between you and us does not preserve novelty against the world. If you publish your invention yourself, or share it in a way that makes it publicly available, that is a disclosure regardless of anything in this clause.
There are three things you can hold.
| What it is | |
|---|---|
| A free account | Costs nothing. Lets you brainstorm and see what the service produces, within the free allowances on our pricing pages. Deliverables carry a watermark |
| A membership | A subscription attached to your account, at the Member, Pro or Max level. Billed monthly or annually. Sets your allowances and which capabilities are available to you, as published on our pricing pages |
| A project grade | A one-time purchase attached to a single project you hold, at the Bronze, Silver or Gold level. Opens the capabilities published for that grade on our pricing pages. Permanent for that project |
Buying a grade does not change your membership. Changing or ending your membership does not affect a grade you have already applied: the project keeps everything its grade includes.
Allowances. Each level and grade carries stated allowances, published on our pricing pages at the time you buy. They apply to all use of your account, whether in our app, through a connected app or with an access token, and connecting another app does not add to them. Allowances restore when the applicable period rolls over, or when you move to a higher level. Reaching an allowance produces a clear message telling you which limit you have reached and how it is restored. It never fails silently.
Automated runs. Some features, such as simulations and the Scenario Director, run steps for you in a loop. They use your allowances as they run. You can set limits where the feature offers them, and you can stop a run at any time.
Annual pricing. Annual memberships are priced at a discount to twelve monthly charges. The discount is shown at the point of purchase.
The member discount on project grades. While your membership is active, you get a discount on project grades and grade upgrades (clause 11). The rate, and whether it combines with a promotional code, are published on our pricing pages and shown at checkout before you pay. Three rules attach to it:
Our merchant of record. From 29 September 2026, payments are processed by Cleverbridge GmbH, of Cologne, Germany, which acts as our authorised reseller and merchant of record. Every purchase made on or after that date is processed this way. This means Cleverbridge is the seller of record to you for the transaction, issues your invoice, and collects and remits any applicable sales tax, VAT or GST.
We never receive your card details. Payment card information is provided directly to the merchant of record and is never transmitted to, stored by, or accessible to us at any point.
Prices and tax. Prices are shown in the currency of your price list. Tax is added at checkout where applicable and shown before you pay.
What you paid, for the purposes of this agreement. Where these terms refer to amounts you have paid us, this includes amounts you have paid to our merchant of record in respect of your account, whether or not they have been remitted to us.
Your dealings with the merchant of record. The merchant of record has its own customer terms governing the payment transaction itself, and its own privacy notice. Both are shown to you at checkout. Those terms govern the payment; these terms govern the service. They cover different things, and we do not agree anything with you that contradicts the merchant of record's customer terms.
Purchases before 29 September 2026. If you bought before that date through another channel, that purchase continues until its term ends, and any renewal is processed by the merchant of record.
Memberships renew automatically at the end of each billing period, at the then-current list price for your item and price list, until you cancel.
We will tell you before we charge you. You will receive notice before each renewal charge. For annual memberships this is at least thirty days beforehand. Where the renewal price differs from the price you last paid, you will receive at least thirty days' notice of the new price before it is charged, whatever your billing period.
You can cancel at any time, from within the service. Cancelling takes no more steps than subscribing did, and we will not put anything in the way of it. Cancellation takes effect at the end of the period you have already paid for, and you keep everything you paid for until then.
Cancelling destroys nothing. When a membership ends, your account returns to the free tier. Your projects, files, documents and history remain. Capabilities that required a paid level become unavailable, and projects beyond the free active-project allowance become read-only rather than being deleted. Archiving a project releases an allowance slot.
Price changes reach you at your next renewal and never mid-term. A price change is never applied to a period you have already paid for.
Failed payment. If a renewal payment fails, the merchant of record will attempt to collect it and will contact you. Your access continues until the end of the period you have paid for. If payment is not collected by then, your account returns to the free tier. Nothing is deleted.
Upgrading a membership. You can move to a higher level at any time. You pay the new level's list price, less a credit for the unused part of your current term, and your current subscription ends. The credit is calculated on whole days, against the amount you actually paid, and in the currency of your original order. It is shown to you on the order and on your receipt before you confirm.
Downgrading a membership takes effect at the end of your current term. Nothing is refunded, because you keep what you paid for until it runs out, and nothing is deleted.
Upgrading a project grade. A grade upgrade is sold as its own item at a fixed price, being the difference between the two grades' list prices. The higher grade supersedes the lower one for that project. Nothing is refunded for the grade you previously bought, and the difference is all you pay.
Grades stay with their project. Once applied, a grade cannot be moved to a different project. If you applied one to the wrong project, contact support@ipguru.ai and we will help.
Refunds are governed by our Refund Policy, which forms part of this agreement, and are processed through the merchant of record.
The service lets you share a project or publish its material. These are powerful features and their consequences are not reversible.
Users under the age of majority. For them, unlisted links, publication and open-sourcing are off by default (clause 5.2).
Sharing to named people. You can share with specific individuals. Their access is revocable, individually, at any time.
Unlisted links. You can create a link that is not listed anywhere and can be opened by anyone who has it. An unlisted link is not confidentiality. It is obscurity plus the ability to revoke. Anyone who has the link, or who is given it, can open what it points to. Treat it as you would treat a key.
Publication and open-sourcing. You can publish material to an external destination such as a website or a code repository. Once published, access is controlled by that destination and not by us, and we cannot recall what has been published.
Defensive publication. Where you use the service to make a defensive publication, we publish it at a public address and issue a signed, timestamped receipt recording what was published, where and when. It stays public for as long as we operate the service, even if you later delete the project or close your account, because a defensive publication only works while it is public. The receipt is evidence of our act of publication. It is not legal advice about the effect of that publication, and whether a defensive publication achieves what you intend is a question for your attorney.
Publication is your decision, and its consequences are yours. Publishing an invention before filing may destroy novelty in most jurisdictions. We will warn you before you publish. We cannot undo it.
Content you publish. You are responsible for what you publish through the service, including that you have the rights to it and that it does not infringe, defame or breach any obligation you owe.
Sending your work to other services. The service may let you send Your Content to a third-party service you choose, such as a prototyping, manufacturing or 3D printing service, a crowdfunding platform, a marketing tool or a laboratory. Each transfer happens only when you choose it. That service's own terms, prices and privacy notice apply to what you send, and you deal with it directly. It is not our sub-processor, our confidentiality obligation in clause 7 ends for what you send, and we cannot recall it. Sending an unfiled invention to anyone without a confidentiality agreement may count as a public disclosure and destroy novelty (clause 3).
Campaigns and marketing. If you use the service to prepare or launch a crowdfunding campaign or marketing, you are its creator and sender. You must follow the platform's rules and the advertising, consumer protection and anti-spam laws that apply to you. Label AI-generated images or video of a product that has not been built as illustrations, and do not claim that a product works, is safe or is certified unless you can show it.
Laboratories and other physical work. The service may let you send instructions to a laboratory or another service that does physical work, such as synthesis, testing or fabrication. Where it does:
Our Acceptable Use Policy forms part of these terms and describes what you may not do with the service. In summary: invent, do not infringe; do not upload material you have no right to use; do not pursue unlawful, harmful or deceptive ends, and never work towards a weapon capable of mass harm; do not upload, request or generate sexual content, or anything that sexualises or abuses a child; and do not attempt to circumvent the safeguards or limits in the service.
We work to keep the service available, and we do not promise it will be uninterrupted or error-free. We may suspend access for maintenance, and where we can, we will give notice.
Rate limits. To protect the service from abuse and keep it responsive for everyone, we apply rate limits and other technical limits, such as how many requests, tasks or connections can run in a period. They apply to every way you use the service, including connected apps and access tokens, and they are separate from your allowances. We set them so that ordinary use within your allowances does not normally reach them, and we may adjust them at any time to protect the service. If you reach one, the request is slowed or refused with a clear message, and you can try again later. Repeatedly exceeding them, or trying to get around them, is a breach of the Acceptable Use Policy.
We may change the service. Features may be added, changed or withdrawn as the product develops. We will not make a change that materially reduces a capability you are currently paying for without giving you at least thirty days' notice, and if we do, you may cancel and receive a refund under section 4 of the Refund Policy.
Preview and experimental features. Some features are marked preview or experimental. They may change or be withdrawn at any time, may be less reliable, and are provided as they are. The notice promise above does not apply to them.
Third-party dependencies. The service depends on third-party providers, including cloud infrastructure and AI model providers. Where a provider changes or withdraws a capability, we may have to change ours.
You may stop at any time, by cancelling your membership or closing your account.
We may suspend or terminate your access if you materially breach these terms or the Acceptable Use Policy, if your use presents a security or legal risk to us or to another customer, or if we are required to by law. Except where the risk requires immediate action, or during an investigation, we will tell you what the problem is and give you a reasonable opportunity to fix it before we act.
Suspension while we investigate. If our safety systems, reports or other signals suggest suspect activity, we may suspend or restrict your account, or any project, feature, connection or token, until our investigation is complete. We tell you that we have done so, unless telling you would create a risk of harm, prejudice the investigation or is prohibited by law. If we find no breach, we restore access promptly, and if you pay for a membership, we extend it by the time you lost. An automatic restriction by our safety systems is temporary, and a person reviews it promptly. A decision to terminate is always made by a person.
Termination for breach. If we find that your account has been used in breach of these terms or the Acceptable Use Policy, we may terminate it without refund, except where the law requires one.
If we terminate for our own convenience, meaning not because of anything you did, we will refund you under section 4 of the Refund Policy and give you at least thirty days to export Your Content.
What survives. Clauses 2 and 3 (what IPGuru is and what we cannot promise), 4 (artificial intelligence), 6 (ownership), 7 (confidentiality), 12 (the consequences of sharing and publication), 16 (your data after the end), 17 (indemnity), 18 (disclaimers), 19 (limitation of liability), 21.12 (messages after your account closes), 22 (governing law) and 23 (general) survive termination, together with the Refund Policy for any refund already due and any amount either of us owes the other.
Export. You can export Your Content at any time while your account is open, in common readable formats together with the files you uploaded, and for thirty days after it closes.
Deletion. You can ask us to delete your data. When you do, we destroy your project material, files and generated outputs, including any copies held for the analytics in clause 6; we keep only what the law requires us to keep, for as long as it requires, and a disabled record of your identity for twenty-four months so that the account cannot be silently recreated and the erasure can be shown to have happened (Privacy Policy section 8). You receive a record of what was destroyed and what was retained, and why.
Archiving a project is different from deleting it. Archiving preserves your files and releases an active-project allowance. Deleting removes the material.
Dormant accounts. An account with no activity for 180 days may be archived, which preserves everything and is undone the moment you sign in. An account with no activity for 18 months may be purged, but only after we have emailed you at fifteen months, at seventeen months, and again thirty days before, with a link to export everything, and only where you hold no paid project grade and no active paid membership. A grade is permanent for its project for as long as we operate the service, so an account holding one is archived and never purged. If we ever close the service, we will give at least ninety days' notice and a way to export everything. Any sign-in resets the clock. The full schedule is in our Privacy Policy.
Backups. Deleted material may persist in backups for a bounded period. Backups are never selectively restored, and any deletion you have requested is re-applied if a backup is ever restored.
Our Privacy Policy describes all of this in detail, including retention periods and your rights.
You indemnify us against any claim, loss, liability, cost or expense (including reasonable legal costs) arising from:
We indemnify you against any third-party claim that the service itself, as provided by us and used in accordance with these terms, infringes that third party's copyright, trade mark or trade secret. This does not extend to output generated for you, to your material, or to any combination of the service with anything we did not provide. Our liability under this indemnity is subject to clause 19.
If you are a consumer, your indemnity under this clause covers only loss caused by your breach of these terms, your fraud or your wilful misconduct.
Each party will notify the other promptly of a claim, allow the indemnifying party to control the defence, and give reasonable assistance. Neither party will settle a claim in a way that imposes an obligation on the other without consent.
To the maximum extent permitted by law, and except as expressly stated in these terms, the service is provided as is and we make no warranties of any kind, whether express, implied or statutory, including any implied warranty of merchantability, fitness for a particular purpose, non-infringement, accuracy or quiet enjoyment.
Nothing in this clause limits any right you have under consumer law that cannot be excluded. Schedule 2 sets out the consumer rights that apply in particular markets, and where they conflict with this clause, they prevail.
Read this clause. It sets the limit of what we owe you if something goes wrong.
What we never exclude. Nothing in these terms limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, for any breach of a consumer right that cannot lawfully be excluded, or for any other liability that cannot lawfully be limited.
What we do not accept. Subject to the paragraph above, we are not liable for indirect, incidental, special, punitive or consequential loss; for loss of profit, revenue, goodwill, anticipated saving or business opportunity; for loss of, or failure to obtain, any patent, patent right or other intellectual property right, except where it is caused by our breach of clause 7; for injury, loss or damage arising from building, testing or using a prototype, product or experiment, or from physical work done by a third party you choose, which is your responsibility; for the consequences of any filing, or any missed deadline; for any consequence of using the service or its output in the diagnosis, treatment or care of any person, which these terms do not permit; or for loss or corruption of data to the extent it results from your own act or omission.
Our total liability, for all claims taken together arising in any twelve-month period, is limited to the greater of:
The floor exists because a cap of nothing is not a cap. If you use the service without paying, you are still owed something if we get it badly wrong.
Where the limit does not apply. The limit above does not apply to our liability for a deliberate breach of clause 7 (confidentiality).
Why the limit is where it is. We charge a software subscription price for a tool that assists your work. We do not charge, and could not sustainably charge, a price that would allow us to underwrite the commercial value of your invention. That value is yours, and insuring it against every possible outcome is not something a tool at this price can do. The limit reflects that bargain, and we have set it out rather than leaving you to work it out.
We may change these terms. When we do:
What stays fixed. The price, allowances and refund terms of a purchase stay as they were when you bought, for that purchase. Every order records the version of these terms you accepted, and you can always retrieve it. Other changes apply from their effective date under this clause.
We have to be able to reach you, and you have to be able to reach us. This clause says how, what we send, and what you control. Only one category is compulsory, and it is small.
| Channel | What it carries | Your control |
|---|---|---|
| Email to your account address | Essential notices about your account, plus any digests, notifications and updates you have configured | Essential ones stay on. Everything else is in your settings |
| Email from our merchant of record | Order confirmations, invoices, notice of an upcoming charge, payment failures, refunds | None. These come from Cleverbridge GmbH because it holds the payment, and they are part of the sale |
| Messages inside the product | Banners, the account and billing pages, the notice that an allowance is nearly used, the reason an action was refused | The essential ones are the service telling you what it is doing. The rest you configure |
| Support conversations, including in-product chat | Whatever you raise with us, and our answer | You start them. We reply on the channel you used unless you ask otherwise |
| Post | Only where a law requires a notice on paper, or where email to you has failed repeatedly | None, and it is rare |
| Text message | A security code, and any alert you have chosen to receive that way | In your settings |
| Marketing and product email | Product news, launches, education, the notify-me list, and messages about IPGuru services related to what you already have | Off in one click, at any time |
| Kind | What it is | Your control |
|---|---|---|
| Essential | Security and access, money, entitlements, the ending or renewal of something you hold, incidents, changes to this agreement, and our answers to you | None while you have an account. See 21.3 |
| Configured | Activity digests, notifications about your projects, alerts when a collaborator does something, allowance warnings, summaries, and anything similar we add later | Complete. On, off, how often, and by which channel. See 21.4 |
| Related services | Messages about IPGuru services close to what you already bought | Off at any time. We also offer the choice when we take your address. See 21.5 |
| Marketing | Product news, launches, education, the notify-me list | Off at any time, and where your market's law requires consent first, we ask first. See 21.6 |
Only the first is compulsory. Ending any of the other three has no effect on your account, your entitlements, your price or the service you receive, and we will not ask you twice.
While you have an account you cannot switch off the messages that tell you what has happened to it. If you could switch them off, you could miss a warning that your password was changed or that your membership is about to end.
The essential category is closed and stays closed. It is limited to: security and access; money, meaning receipts, charges, failures and refunds; entitlements and what you can now do; the ending or renewal of something you hold; availability and incidents; changes to these terms, the Privacy Policy or our sub-processors; and our answer to something you asked. We will not add to that list without changing these terms under clause 20, which carries thirty days' notice and your right to leave. The limit is on what is compulsory. It is not a limit on what the service can tell you, because everything else in 21.4 is yours to configure.
You decide what the service tells you, how often, and where. Your settings control activity digests, notifications about your projects, alerts when someone you have shared with does something, warnings that an allowance is nearly used, periodic summaries, and any similar message we introduce later.
We choose the default, you change it. A new notification arrives with the setting we think most people want and appears on the same page as the rest, so there is one place to look. Turning these off leaves your account working exactly as it did, and never affects an essential message.
They are not marketing and do not need your consent, because they report your own activity on a service you asked for. They may point you at a feature that would help with what you are doing.
If you are or have been a customer, we may write to you about IPGuru services similar to what you already have. We offer you the chance to decline when we take your address, every such message carries a one-click opt-out, and declining costs you nothing. We never send these messages to a user under the age of majority (clause 5.2).
Where the law of your market requires your consent before we do this, we ask for it first and this paragraph does not apply to you until you give it. Your Market Schedule states the position for your market.
An essential message never carries a promotion. Not a banner, not a footer offer, not a while you are here. The moment a receipt carries a promotion the whole receipt becomes marketing, and our ability to send you the receipts you actually need depends on our never having done that.
Configured messages and messages under 21.5 may carry product news, because you can switch them off. Messages to a minor never do (clause 5.2).
To you. Email to the address on your account is effective notice under these terms, treated as received on the day we send it, or on the next business day where you are if we send it outside business hours. Where email to you has failed repeatedly we may give notice inside the product, and that is effective too. Where the law of your market requires a different method or a longer period, the Market Schedule says so and that requirement applies.
To us. Write to support@ipguru.ai for anything about your account or an order, or to the registered office in clause 1 for a formal legal notice. Notice to us takes effect when we receive it, or on the next business day in Singapore if it arrives outside business hours.
Two things that are deliberately not notices, so that you are not caught out:
The email address on your account is how we reach you, so keep it current. We verify it when you register and again whenever it changes, and until a new address is verified we keep writing to the old one. If mail to you bounces repeatedly we may stop sending to that address and tell you inside the product instead. That does not suspend your account.
We write to you in English unless the Market Schedule for your market says otherwise. Where a market requires communications in another language, that requirement applies and its schedule states it.
Support conversations, including chat, and a record of the messages sent to you are kept as part of your account record for the periods in the Privacy Policy. We keep them so that a question about what you were told has an answer rather than two recollections.
Essential messages stop when your account closes, except where we still have to reach you: a security incident affecting your data, a legal or tax obligation, or a payment matter such as a refund or a disputed charge. Configured messages stop, because there is no activity to report.
Messages under 21.5 and 21.6 may continue where the law of your market allows it, and the one-click opt-out in every one of them still works. If you would rather hear nothing further, tell us or use that link and we will stop.
These terms are governed by the law of Singapore, and the courts of Singapore have jurisdiction, except that:
Before you sue us, talk to us. If something has gone wrong, contact support@ipguru.ai and give us thirty days to try to resolve it. Most problems are solved faster this way than by either of us instructing lawyers. This is not a condition of your right to bring a claim.
Entire agreement. These terms, your Market Schedule, the Acceptable Use Policy, the Refund Policy, the Privacy Policy, and the details of your order with the pricing pages as they stood when you bought, are the entire agreement between us about the service, and replace any earlier statement or understanding. Where they conflict, your Market Schedule prevails as clause 1.1 says; otherwise these terms prevail over the policies, and the policies over the order and pricing pages, except that the price and allowances stated for an order apply to that order. An institution's own terms (clause 5.1) govern only your relationship with that institution. Nothing in this clause limits liability for fraudulent misrepresentation.
Severability. If any provision is held unenforceable, it is modified to the minimum extent necessary to make it enforceable, or if that is not possible, severed. The rest continues in force.
No waiver. If we do not enforce a right, that is not a waiver of it.
Assignment. You may not assign these terms without our consent. We may assign them to an affiliate, or in connection with a merger, acquisition or sale of the business, on notice to you.
No third-party rights. No one other than you and us has any right to enforce these terms.
Force majeure. Neither of us is liable for a failure caused by an event beyond reasonable control, provided the affected party takes reasonable steps to mitigate and resume. It does not remove a refund you are owed.
Export control and sanctions. We comply with the sanctions and export control laws of Singapore, including those that implement United Nations Security Council sanctions. As far as Singapore law allows, we also comply with the sanctions and export control laws of the United States. We do not provide the service to you, and you may not use it:
We decide which countries and regions to block under those laws, and the list may change without notice. Do not use a VPN, a proxy or false details to get around a block. If an account falls under a restriction, we may suspend or close it, and any refund is subject to what those laws allow. Our merchant of record also screens orders under the sanctions laws that apply to it. You confirm that none of these restrictions applies to you.
| Storefront | Market Schedule | Market | Seller | Merchant of record |
|---|---|---|---|---|
ipguru.ai | MS-GLOBAL | Every market without a specific schedule | Corvair Pte. Ltd. | Cleverbridge GmbH |
invent.sg | MS-SG | Singapore | Corvair Pte. Ltd. | Cleverbridge GmbH |
ipguru.ai, Australia price list | MS-AU (in preparation) | Australia | Corvair Pte. Ltd. | Cleverbridge GmbH |
ipguru.ai, United States price list | MS-US (in preparation) | United States | Corvair Pte. Ltd. | Cleverbridge GmbH |
ipguru.ai, India price list | MS-IN (in preparation) | India | Corvair Pte. Ltd. | Cleverbridge GmbH |
Storefronts differ in brand, language, currency, price list and tax presentation. The seller, the service and these terms are the same in every case.
Institutions are not storefronts. A cohort or licensed deployment (clause 5.1) runs under an agreement between us and the institution. Your account shows when you take part through one, and links the institution's terms.
Where a Market Schedule has not yet been issued for your market, you contract under MS-GLOBAL and these terms, and you keep the benefit of any mandatory law of your own country regardless.
Your order records both versions: the version of these terms you accepted and the version of your Market Schedule. You can always retrieve the pair you accepted, not only the current ones.
If a market ever needs its own selling entity, that is not a Market Schedule. It is a different contracting party and a different privacy controller, and it requires a change to these terms naming that entity before it can sell anything.
Nothing in these terms affects a right you have under consumer law that cannot be excluded by agreement. The following is the global baseline. Your Market Schedule may add to it, and where the law of your country gives you more, the law applies.
European Union and United Kingdom. You have a right to withdraw from a distance contract for digital content within fourteen days, without giving a reason. Where you ask us to begin providing the service immediately, and acknowledge that you lose the right of withdrawal once performance has begun, that right ends when we begin. We ask for that acknowledgement at checkout, because a project grade begins generating work as soon as it is applied. Where performance has begun but is not complete, you may withdraw and pay for what has been provided.
Australia. Our goods and services come with guarantees that cannot be excluded under the Australian Consumer Law.
Singapore. The Consumer Protection (Fair Trading) Act 2003 applies to consumer transactions and is not excluded by these terms.
United States. Some states do not allow the exclusion of certain warranties or the limitation of certain damages, so some of the limitations above may not apply to you.
Grade means a one-time upgrade applied to a single project, at the Bronze, Silver or Gold level.
Level means the membership tier attached to your account, being Member, Pro or Max.
Cohort means a class, course, hackathon, competition, event or other group set up in the service by an instructor or organiser for an institution, which participants join (clause 5.1).
Dedicated platform means an instance of the service for one institution, operated by us as a managed service or run in the institution's own cloud tenancy, under a written agreement (clause 5.1).
Institution means a school, university, training provider, education authority, government agency or programme, employer, event or competition organiser, or other organisation that provides the service to its students, staff, members or participants, or pays for them to use it, including under a sub-licence or on a dedicated platform, under an agreement with us.
Merchant of record means the party that sells to you as reseller, invoices you, and collects and remits tax. Ours is Cleverbridge GmbH, from 29 September 2026.
Chat and generation history means the record of your conversations with the service and of the outputs it generated for you. Clause 6 sets the rules for analysing it to improve the service.
Connected app means an application you authorise to use the service on your behalf, through our connector or with a personal access token.
Output means any document, analysis, search result, draft or other material the service generates for your project.
Project means a container holding one idea or invention, together with its knowledge base, its working memory and its file vault.
Essential message means a message we send you about your account, your orders, your entitlements or this agreement, of a kind listed in clause 21.3. It is not marketing, it does not require your consent, it never carries a promotion, and it cannot be switched off while you have an account.
Configured message means any other message the service sends you about your own activity, which you turn on, turn off, schedule or redirect in your settings under clause 21.4.
Sub-processor means a third party that processes your material on our behalf in order to provide or improve the service. Our current sub-processors are listed in the Privacy Policy.
Your Content means everything you upload, enter or connect to the service, and everything the service generates for you, including brainstorms, projects, conversations, documents, files and outputs. Where these terms or our policies say "your material", "your invention material", "project content" or "your content", they mean Your Content.
Telemetry means information about how the service is used and how it performs, as distinct from Your Content. It includes technical logs, hashes, summary statistics and classifications, metrics and learnings; sign-in, session and presence events; feature use, and page and interaction timings; request rates, response codes, errors, timeouts, retries and provider faults; allowance, cost and model-usage records; storefront and market; safety events; and the results of service health checks. Telemetry can be derived from Your Content, for example a classification of a request or a hash of a file, but it does not contain Your Content.
Safety reports means our internal records of what our safety systems flag, which our trained safety staff review.
Under the age of majority, and minor, mean under 18 years old.
Corvair Pte. Ltd. (UEN 202551453H), 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216, is the controller of the personal data described in this policy.
Data Protection Officer: Christopher Jackson, reachable at privacy@ipguru.ai. You can contact our DPO about anything in this policy, including a request to exercise your rights.
This policy covers ipguru.ai, invent.sg and any other storefront we operate. It is written to meet the Singapore Personal Data Protection Act 2012 and, where it applies to you, the EU and UK General Data Protection Regulation.
There is one privacy policy, not one per market. IPGuru is a single service operated from Singapore, so there is one controller, one set of processing operations and one set of sub-processors, whichever storefront you arrived through. A separate policy per market would drift, and would mean the same request answered differently depending on which page you had read.
Where a market needs local particulars, they appear in a short market annex at section 15 carrying only the local supervisory authority, the local complaint route and any local representative. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it.
Schools, employers, events and other institutions. When you take part through an institution's cohort, workplace or licensed deployment, or dedicated platform (Terms clause 5.1), the institution may be the controller of some of your personal data, such as your enrolment and the work its cohort, event or programme makes visible, and we process that data on its behalf under a written agreement. Where that is so, the institution's privacy notice also applies, and you can send a request to either of us. We will pass on a request that belongs to the institution. Where a dedicated platform runs in the institution's own cloud tenancy, the institution controls that platform's infrastructure and data, and its own providers and privacy notice apply as its agreement with us says.
Four things are worth stating before the detail, because they are the questions people actually ask.
We do not sell your personal data. Not to anyone, for any purpose, ever.
We do not use your invention material to train AI models. Your uploads, your generated documents and your project conversations are not used to train, fine-tune or improve any AI model, ours or a third party's. We contract with our model providers on terms that prohibit it. We do analyse chat and generation histories by automated means to improve the service's own software. Nothing from your content is reused for another customer, and you can opt out. Section 3 explains.
We do not read your content as a matter of routine. Our support team sees the shape of your account, not its contents. Staff can see your content only in the cases listed in section 4, and every access is recorded.
We do not use your data for advertising, and we do not build advertising profiles.
Connected apps. A connected client holds a connection token that works only through the connector, never your password. We record the connection, the client's name, its permissions, when it was last used, and its actions as connector activity. You can revoke each connection independently without ending your browser session. When a connected app asks for your content, we send it to that app at your instruction. The app is not our sub-processor, and its own terms and privacy notice govern what it does with that content.
| Category | What it includes | Why we process it | Legal basis (GDPR) |
|---|---|---|---|
| Account data | Name, email address, the identity provider you sign in with, your date of birth or birth year, account settings, verification status | To create and operate your account, authenticate you, and secure it | Performance of a contract |
| Project content | Everything you upload or the service generates for you: invention descriptions, documents, drafts, files, research, conversations | To provide the service you asked for | Performance of a contract |
| Commercial data | Orders, entitlements, membership level, project grades, invoices, refunds, the storefront you bought through | To sell you the service, honour what you bought, and keep accurate records | Performance of a contract; legal obligation for tax records |
| Telemetry | Telemetry as the Terms of Service define it: technical logs, hashes, summary statistics and classifications, metrics and learnings; sign-in, session and presence events; feature use and timings; request rates, errors and provider faults; allowance, cost and model-usage records; safety events and health-check results. It contains none of your content | To run, secure and improve the service, diagnose faults and enforce allowances | Legitimate interests: operating a reliable and secure service |
| Security data | IP address, device and browser information, authentication events, step-up events, audit records | To detect and prevent abuse, fraud and unauthorised access | Legitimate interests: security; legal obligation |
| Safety data | Automated safety flags on requests, uploads and outputs, and the record of any safety review | To prevent prohibited and dangerous uses, protect people, and meet our legal obligations | Legitimate interests: preventing serious harm; legal obligation |
| Support data | Your messages to us, and our record of what we did | To help you, and to keep a record of it | Performance of a contract; legitimate interests |
| Service improvement analytics | Chat and generation histories: your conversations with the service and the outputs it generated for you | Automated analysis to improve the service's filters, safety guardrails, prompts, templates, instructions, guidelines, rubrics, policies and other internal software. Nothing from your content is copied into anything used for another customer | Legitimate interests: improving the quality and safety of the service. You can object at any time (section 9) |
| Cohort and consent data | The cohorts and deployments you join, your role, enrolment dates, what the cohort makes visible, and, for a student under the age of majority, the record of how consent was given | To run the cohort, give the instructor the read-only access its terms allow, and show that consent was given | Performance of a contract; where an institution is controller, its instructions; legal obligation for consent records |
| Marketing data | Your consent, when you gave it, from which page, and under which terms version | To send you material you asked for | Consent |
Service improvement analytics. Our systems, and the sub-processors listed in section 5, analyse chat and generation histories to find where the service falls short and to improve its own software. We never copy your content, or any excerpt, detail or example from it, into a prompt, template, rubric or other part of the service used for another customer. This is not model training, and the promise in section 2 still applies. To opt out, write to privacy@ipguru.ai. We act on it within thirty days, and opting out does not change your service or your price.
We do not collect payment card details, bank details or government identification numbers. Payment information goes directly to our merchant of record and never reaches us.
Health data. Health and medical inventions are welcome, but the service is not for clinical use and we do not want health records. Do not upload identifiable health information about a patient or any other person; use anonymised or synthetic data (Terms clause 2). We are not a healthcare provider, health plan or healthcare clearinghouse, or a business associate of one under HIPAA, and we do not hold health records for anyone. If identifiable patient data reaches us, we may delete it.
Children and students under the age of majority. The minimum age for an account you create yourself is fifteen, and higher in some markets. Younger users can take part with the permission of a parent or guardian, or when a school, education authority or government programme enrols them under a written agreement with us, with consent given by the institution where the law allows it, or by a parent or guardian who opts in (Terms clause 5.2). Apart from that, we do not knowingly collect personal data from anyone below the applicable minimum; if you believe we have, contact our DPO and we will delete it. Where the law requires verifiable parental consent, such as for children under 13 in the United States, we obtain it in the form that law sets. For any user under 18 we send no marketing, keep publishing off by default, accept no purchases from the user, and leave them out of service improvement analytics unless a parent or guardian, or the institution where the law allows it, opts them in. A parent or guardian can exercise the rights in section 9 on the child's behalf.
Each project is isolated. A project has its own knowledge base, its own working memory and its own file vault. Access is decided per request by a policy engine that denies by default: if it cannot reach a decision, it refuses rather than allowing.
Sharing is yours to control. A project is private until you share it. You can share with named people and revoke each of them individually, or create an unlisted link. An unlisted link can be opened by anyone who has it, so treat it as a key rather than as a secret.
Uploads are scanned for malware and prohibited content, including sexual content and material that sexualises or abuses a child, before anything enters your knowledge base. Items that fail are quarantined and never enter it.
Sensitive actions require you to re-authenticate. Deleting a project, transferring ownership, exporting your data, changing your credentials, erasing your account and publishing all require a fresh authentication, even if you are already signed in.
When our staff can see your content. Our support team sees the shape of your account, not its contents, and there is no standing access. Staff can see your content only: when you ask for help and approve a time-limited support access grant; in a safety review of what our automated systems flag; in an investigation of suspect activity; where the law requires it; or to review examples picked out by service improvement analytics, unless you have opted out (Terms clause 7). Every access is recorded. Support access and analytics reviews always appear in your activity log. The others appear there unless telling you would create a risk of harm, prejudice an investigation or is prohibited by law.
Safety review. Automated systems check requests, uploads and outputs for prohibited uses. Where they flag weapons development or a serious risk of harm, such as work towards a weapon capable of mass harm, material that sexualises or abuses a child, or a credible threat to someone's life, a trained member of our team may review what was flagged. The review is limited to what was flagged.
We share personal data only with the following, and only as far as necessary.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud Platform | Application hosting, database and file storage | United States (us-central1) |
| Google Firebase / Identity Platform | Authentication and identity | United States |
| Permit.io | Authorisation decisions. Receives identifiers and entitlement attributes, never content | United States / EU |
| Neo4j Aura | Graph database supporting research features | United States |
| Google Gemini | Generation of drafts, analysis, research output, images and video, including the Gemini image and Veo video models, and Model Armor safety screening. Contracted on terms that prohibit training on your content | United States |
| TypeSafe AI, Inc. | Jev decision model, used for scoring, grading and classification. Being introduced. Contracted on terms that do not permit training on your content without our consent, which we do not give. TypeSafe may keep Telemetry about our requests, which contains none of your content | United States |
| Exa Labs, Inc. | Web search, grounded search and citations for research. Receives search queries, which may include terms drawn from your content, and the addresses of pages to read | United States |
| GoVeda Pte. Ltd. | Patent database search and retrieval. Receives search queries, which may include terms drawn from your content. Its published terms state that queries are not used to train models | Singapore and other locations |
| Google Analytics | Analytics on the ipguru.ai website, with consent where required. Receives pages visited and device information, never your content | United States |
| Mailgun | Delivery of service email | United States |
We publish changes to this list, and email you at least thirty days before a new sub-processor begins processing your content. If you object, tell our DPO. If we cannot address your objection, you may cancel and receive a refund of the unused part of your membership.
From 29 September 2026, Cleverbridge GmbH sells to you as our authorised reseller and merchant of record. For the payment transaction it is a separate and independent controller of the personal data it collects from you, not our processor, and its own privacy notice governs that data. We receive from it your order reference, the product bought, and your contact email address. We never receive your payment card details.
If you join a cohort or take part in a workplace or licensed deployment, the instructor, organiser, judges, mentors, reviewers and other people the institution names can see, read-only, the work its terms make visible and anything else you choose to share, with your name, enrolment and progress. The institution receives what its agreement with us provides. It does not receive your other work. At the end of a cohort this access ends unless you choose to keep it. In a workplace deployment, the organisation's rules decide what happens to that work when you leave.
We may disclose personal data where we are legally required to, to establish or defend a legal claim, or to protect the safety of a person or the public, including when we report a serious risk to life or public safety, or child sexual abuse material, to the authorities. When an authority asks us for data, we check that the request is lawful, disclose only what it requires, and tell you unless the law forbids it or telling you would create a risk of harm. In a merger, acquisition or sale of the business, data may transfer to the acquirer under the same protections, and we will tell you.
We never share your content with anyone for their own purposes. It leaves us only in the cases listed in clause 7 of the Terms of Service.
We are established in Singapore and our infrastructure is currently hosted in the United States. If you are in the EU, the UK or another region with transfer restrictions, your personal data is transferred outside that region.
We rely on Standard Contractual Clauses with our providers, together with the technical measures described in sections 4 and 11, as the basis for those transfers. You can request a copy of the relevant clauses from our DPO. Where the Singapore PDPA applies, we transfer personal data outside Singapore only to recipients bound, by contract or by law, to protect it to a standard comparable to the PDPA.
We are evaluating regional hosting for other markets. If we introduce it, we will update this policy before any data moves.
| Data | Retention | Trigger for disposal |
|---|---|---|
| Account data | While your account is open | Account closure, then deletion after the erasure process completes |
| Project content | While your account is open, or until you delete the project | Your deletion, or thirty days after account closure, so you can export it |
| Archived projects | Until you delete them | Your deletion |
| Dormant account, archived | From 180 days without activity | Archiving is automatic and reversible. See section 8 |
| Dormant account, purged | From 18 months without activity, after notice, and only where no paid project grade or active paid membership is held | See section 8 |
| Commercial records: orders, invoices, tax | Five years from the end of the relevant financial year | Statutory retention period expiry |
| Security and audit records | Twelve months, or longer where needed for an open investigation | Period expiry, or closure of the investigation |
| Safety review records | Twelve months, or longer where needed for an open investigation or a report to the authorities | Period expiry, or closure of the investigation |
| Telemetry | Up to thirteen months | Period expiry |
| Service improvement analytics | Working copies of chat and generation histories are kept no longer than the project they came from. Findings that contain none of your content may be kept | Deletion of the project or account, or your opt-out |
| Support correspondence | Twenty-four months from closure | Period expiry |
| Marketing consent records | While consent stands, and three years after withdrawal as evidence that it was withdrawn | Period expiry |
| Cohort membership and instructor access | While the cohort runs | End of the cohort, unless you choose to keep it, or your leaving |
| Consent records for users under the age of majority | While the account is open, and afterwards only as long as the law requires us to show that consent was given | Period expiry |
| Identity record after erasure | Retained in disabled form | See section 8 |
| Backups | Bounded window, currently thirty-five days | Rotation |
You can delete a project at any time from within the service.
You can erase your account. When you do:
What survives an erasure, and why. Your identity record is disabled rather than deleted, retaining your identifier and email address. This is so that the account cannot be silently recreated and so that we can prove the erasure happened if you or a regulator ask. The legal basis is our legitimate interest in the integrity of the erasure, and it is disposed of after twenty-four months. We tell you this before you confirm, not afterwards.
Archiving is not deleting. Archiving preserves your material and frees an active-project slot.
Keeping data forever is not a kindness, so accounts that go quiet are handled on a stated schedule rather than left indefinitely.
| After | What happens | Reversible? |
|---|---|---|
| 180 days with no activity | Your account and its projects may be archived. Everything is preserved. Archiving frees resources and active-project allowance | Yes, immediately. Sign in and it is restored |
| 15 months | We email you to say the account is dormant, what will happen, and how to keep it | — |
| 17 months | We email you again | — |
| 30 days before purge | A final email, with a link to export everything | — |
| 18 months with no activity | The account and its material may be purged, subject to the exception below | No. This is permanent |
Any sign-in resets the clock. Opening the service, exporting, or replying to one of the notices all count as activity.
Accounts holding a paid project grade or an active paid membership are never purged. A grade is sold as permanent for its project, for as long as we operate the service, and purging it for inactivity would take away something that was paid for. Those accounts are archived and stay archived. If we ever close the service, we will give at least ninety days' notice and a way to export everything.
We would rather you kept your work than that we saved the storage. Invention is intermittent by nature, and a year between sessions is normal rather than abandonment, which is why the notices start at fifteen months and why a single sign-in is enough to stop the process.
Whether you are covered by the PDPA, the GDPR or both, you can:
How to exercise them. Most are available directly in the service: export, deletion and correction are self-service. For anything else, contact privacy@ipguru.ai. We respond within thirty days and will tell you if we need longer.
Complaints. If you are unhappy with how we have handled your data, tell us first and we will try to fix it. You can also complain to the Personal Data Protection Commission of Singapore, or, if you are in the EU or UK, to your local supervisory authority.
Clause 21 of the Terms of Service sets out every channel we use, what each carries and what you control. This section says what those communications mean for your personal data.
Four kinds of message, kept separate on purpose:
| Kind | Examples | Our legal basis | Your control |
|---|---|---|---|
| Essential | Sign-in and security notices, receipts, entitlement changes, an expiring share, a completed export, material changes to these policies, our answer to a request you made | Performance of our contract with you, and our legal obligations | None while you have an account. You cannot unsubscribe from being told your credentials changed |
| Configured | Activity digests, project and collaborator notifications, allowance warnings, periodic summaries | Performance of our contract, and our legitimate interest in operating a service that tells you what it is doing | Complete. On, off, how often, and by which channel, in your settings |
| Related services | Messages to a customer about IPGuru services similar to what they already have | Our legitimate interests, in markets that permit this. Where your market requires consent first, consent | Off in one click, at any time, and we offer the choice when we take your address |
| Marketing | Product news, launches, education, the notify-me list | Consent where your market requires it, otherwise our legitimate interests | Off in one click, at any time, honoured everywhere |
No marketing to users under the age of majority. They receive essential and configured messages only, never marketing or messages about our other services.
An essential message never carries marketing. The moment a receipt carries a promotion, the whole receipt becomes marketing, and our ability to send you the receipts you actually need depends on not having done that.
Consent, where we rely on it, is active and recorded. No pre-ticked boxes, no consent bundled into accepting the terms or into a purchase. We record what you agreed to or declined, when, from which page and under which version. Where we rely on legitimate interests instead, you have the right in section 9 to object, and for direct marketing an objection is absolute: we stop.
Where a market allows us to write to our own customers about related services without asking first, we use it, and we always give you the choice when we take your address and an opt-out in every message. Your Market Schedule states the position for your market.
We do not currently market by telephone call or text message. A text from us is a security code, or an alert you asked to receive that way. If that ever changes we will meet the rules of the market first, including any do-not-call register.
We never pass your contact details to anyone else to market to you, and we do not sell or rent them.
Our merchant of record writes to you as well. Cleverbridge GmbH sends order confirmations, invoices and payment notices as the seller of record for the transaction. For that purpose it is a controller in its own right, under its own privacy notice, and those messages cannot be switched off because they are part of the sale.
If you subscribed to a list without an account, you have given us an email address and nothing else. You have no account and no profile, and the rights in section 9 apply to that record exactly as they would to any other.
We keep a record of what we send you, including support conversations, for the periods in section 7. It is kept so that a question about what you were told has an answer.
The measures we rely on include: encryption of data in transit and at rest; multi-factor authentication; a policy decision point that denies by default; step-up re-authentication for sensitive actions; per-project isolation of storage; short-lived data-plane credentials that can only be narrowed and never widened; keyless deployment credentials; malware scanning of uploads; an append-only audit ledger that is never edited; daily backups replicated to redundant storage; and a documented business continuity and disaster recovery plan.
Breach notification. If a data breach occurs that is likely to result in significant harm to the people affected, or that affects 500 or more people, we will notify the PDPC within three calendar days of assessing it as notifiable, and affected individuals as soon as practicable where significant harm is likely. Where the GDPR applies, we will notify the supervisory authority within seventy-two hours and affected individuals without undue delay where the risk is high. We will tell you what happened, what data was involved, what we have done, and what you should do.
No security is absolute. We will tell you promptly and honestly if something goes wrong.
We use cookies and local storage for three purposes: strictly necessary (keeping you signed in, security, load balancing), preferences (remembering your settings), and analytics (understanding how the service is used so we can improve it).
Strictly necessary cookies do not require consent. Where consent is required for analytics or preferences in your market, we ask for it before setting them and you can change your mind at any time. We do not use advertising cookies or third-party tracking for advertising.
We will publish any new version with a version number and effective date. For a change that materially affects your rights, we will give you at least thirty days' notice by email before it takes effect.
Data Protection Officer, Corvair Pte. Ltd. privacy@ipguru.ai 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216
Local particulars only. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it. Everything above this section applies to you wherever you are.
Singapore. Corvair Pte. Ltd. is established in Singapore and the Personal Data Protection Act 2012 applies to our handling of your personal data. Supervisory authority: the Personal Data Protection Commission, pdpc.gov.sg. Our Data Protection Officer, named in section 1, is the contact for any access, correction or withdrawal-of-consent request under the Act, and for any complaint. If we do not resolve a complaint to your satisfaction you may take it to the Commission.
European Union. The GDPR applies to our processing of your personal data. Sections 3, 6, 7 and 9 state our legal bases, our retention periods, the rights you hold and the safeguards for transfers. Because we host in the United States, every transfer is made under the European Commission's standard contractual clauses with each recipient, supported by a transfer risk assessment. You may complain to the supervisory authority of the member state where you live, where you work, or where the matter arose, and you may do so without contacting us first, although we would rather you gave us the chance to fix it.
United Kingdom. The UK GDPR and the Data Protection Act 2018 apply on the same terms as the paragraph above, with transfers made under the UK International Data Transfer Addendum to the standard contractual clauses. Supervisory authority: the Information Commissioner's Office, ico.org.uk.
Australia. The Australian Privacy Principles under the Privacy Act 1988 apply to our handling of your personal information. Under the Notifiable Data Breaches scheme we will notify the Commissioner and affected individuals as soon as practicable where a breach is likely to result in serious harm. You may ask us for access to or correction of your information under APP 12 and APP 13, and section 9 tells you how. Supervisory authority: the Office of the Australian Information Commissioner, oaic.gov.au.
Every other market. Where we have not published an annex for your market, this policy applies to you in full and nothing is reduced by the absence. You may complain to your local data protection authority, or to the Personal Data Protection Commission in Singapore, where we are established.
Every way in is covered. Connected apps using our MCP connector, and personal access tokens, are covered by this policy in the same way as our own app. Keep each personal access token secret.
Invent, do not infringe. The service exists to help you develop your own invention. It is not a tool for copying someone else's.
With other people's intellectual property
With the law
Weapons of mass harm and other serious harm
These rules apply whatever the stated purpose. Legitimate work in medicine, public health, biosafety, biosecurity and protection against these threats is welcome, but the service will refuse help that would give meaningful capability to cause mass harm, however the request is framed.
Weapons and defence technology. Other work on weapons, defence and security technology is not prohibited in itself, except as this section and the law restrict it. It must comply with the law, including the export controls in clause 23 of the Terms. Our safety systems flag it for our safety reports, and it may be reviewed and investigated (section 3).
With other people
With the service itself
We scan uploads. Files are checked for malware and prohibited content, including sexual content and material that sexualises or abuses a child, before entering your knowledge base. Items that fail are quarantined and do not enter it.
We monitor for abuse, using content-free operational signals such as request rates and error patterns. We apply rate limits to every way into the service, including connected apps, and slow or refuse requests that exceed them.
Our safety systems work in layers. The safety guardrails built into the AI models we use, Google Cloud Model Armor, Google Cloud Armor at the edge of our network, and our own filters, prompts and checks screen requests, uploads and outputs, including generated images and video. Together they catch, block or redirect requests for prohibited or restricted content, and they refuse work that section 2 prohibits. Weapons development that section 2 does not prohibit is flagged for our safety reports, not blocked.
We do not read your content to police it, except in the cases listed in clause 7 of the Terms. The main one is a safety review: where an automated system flags weapons development or a serious risk of harm, such as work towards a weapon capable of mass harm, material that sexualises or abuses a child, or a credible threat to someone's life, a trained member of our team may review what was flagged, and it may lead to an investigation.
When something is wrong, we will usually tell you first. Except where the risk requires immediate action, or an investigation requires otherwise, we will describe the problem and give you a reasonable opportunity to fix it before we restrict anything.
What we may do: refuse or quarantine specific content; restrict a feature; suspend an account; terminate an account for material or repeated breach; keep the records we need; and report to the authorities where the law requires it, or where we believe there is a serious risk to life or public safety. Where the breach involves a weapon capable of mass harm, material that sexualises or abuses a child, a sanctions restriction or a credible threat to life, we may act at once and without notice.
Investigation. If we detect suspect activity, we may suspend or restrict an account until our investigation is complete. An account found to have breached the Terms or this policy may be terminated without refund, except where the law requires one.
If we get it wrong, tell us. Contact support@ipguru.ai and we will review it. Automated safety systems make mistakes, and an appeal reaches a person.
To report misuse, infringement of your rights, or content that should not be on the service, contact abuse@ipguru.ai with enough detail for us to find it. We respond to every report.
If you say material infringes your rights, include your contact details; the work or right you say is infringed; where the material is, such as a link or project reference; and a statement that you believe the use is not authorised and that your notice is accurate. We review every notice, may remove or restrict the material, and tell the account holder, who can respond. We restore the material if the response shows the claim is mistaken, unless the law or a court order prevents it.
You can start free. You can create an account, start a project and see what the service produces without paying anything. We would rather you found out the service is not for you before you buy than afterwards.
Fourteen days, no questions. If you cancel a new membership within fourteen days of your first payment, we refund it in full. This applies to your first membership purchase, not to each renewal.
Renewals. We notify you before every renewal charge, at least thirty days ahead for annual memberships. If a renewal catches you by surprise despite that notice, contact us within fourteen days of the charge and we will refund it, provided you have not made substantial use of the service in that period.
Mid-term cancellation. You can cancel at any time. Cancellation takes effect at the end of the period you have paid for and is not refunded, because you keep the service until then.
Upgrades. When you upgrade, we do not refund your current term. We credit its unused value against the new one, calculated on whole days and against what you actually paid. The credit is shown before you confirm.
The member discount. An active membership discounts project grades and grade upgrades, at the rate on our pricing pages when you buy. Refunds are always calculated on what you actually paid after that discount, never on the list price. Losing a membership does not claw back a discount already given.
Grades are one-time purchases that unlock generative work carrying real cost, so the position depends on whether that work has been run.
| Situation | Outcome |
|---|---|
| Bought, not yet applied to a project | Full refund, within thirty days |
| Applied, no generative work run | Full refund, within fourteen days |
| Applied, some generative work run | Partial refund, reduced by the work consumed, within fourteen days. We show you the calculation |
| Applied, substantially consumed | Not ordinarily refundable, but ask us. See section 5 |
| Grade upgrades | The same rules apply to the upgrade item. The grade you previously held is not refunded |
In full, whatever the timing, if we charged you in error or twice, or if the law where you live requires it.
For the unused part, if:
For a membership, the unused part is the rest of your current term, calculated on whole days against what you paid. For a project grade, it is the price you paid less the value of the work already run, calculated as in section 3.
Accounts closed for a breach. If we close your account because it was used in breach of the Terms or the Acceptable Use Policy, we do not refund, except where the law requires it.
Policies cannot anticipate everything. If something has gone wrong and this policy does not cover it, contact support@ipguru.ai and explain. We would rather refund a customer who feels badly treated than argue about a clause. A dispute costs us more than a refund does, and it costs you your afternoon.
European Union and United Kingdom. You have a right to withdraw from a distance contract for digital content within fourteen days without giving a reason. Where you ask us to begin immediately and acknowledge at checkout that you lose that right once performance begins, the right ends when we begin. Where performance has begun but is incomplete, you may withdraw and pay only for what was provided.
Australia. Our services come with guarantees that cannot be excluded under the Australian Consumer Law, including a right to a refund for a major failure.
Singapore. Your rights under the Consumer Protection (Fair Trading) Act are not affected by this policy.
Nothing here limits a statutory right. Where the law gives you more than this policy does, the law applies.
If something is wrong with a charge, contact us first. We will almost always resolve it faster than your bank will, and section 5 means we would rather refund you than argue about it.
Starting a chargeback without contacting us may result in your account being suspended while we investigate. A chargeback reverses a payment without telling us why, so we cannot fix the underlying problem and we cannot tell a mistake from a fraud. We will tell you it has happened and what we need from you, and we will restore the account as soon as it is resolved.
Where we hold evidence that a charge was valid, we may present it to the payment provider. If a chargeback is resolved in our favour, any outstanding balance remains payable.
None of this affects your right to dispute a charge with your bank. It affects only the order in which we would rather you did it, and the reason is simple: a refund costs us less than a chargeback does, so talking to us first is the outcome we are trying to buy.
Contact support@ipguru.ai with your account email and the order reference from your receipt. We aim to respond within two business days and to complete an approved refund within ten business days, though the time for the money to reach your account depends on your payment provider.
Refunds are made in the currency you paid, for the amount you paid. Exchange rate movement between purchase and refund is ours to absorb, not yours.
A Data Processing Agreement for business, organisation and educational customers is in preparation and will be published before we onboard those customers, including schools and other institutions under clause 5.1 of the Terms of Service.
Controller. Corvair Pte. Ltd. (UEN 202551453H) is the controller of personal data processed through the platform for individual customers. Where we process personal data on behalf of an organisation, we act as processor and a Data Processing Agreement will govern that relationship.
Sub-processors. The current list is published in our Privacy Policy and is maintained there. It is the authoritative list.
Security measures. Described in the Privacy Policy. Encryption in transit and at rest, multi-factor authentication, per-project isolation, an authorisation decision point that denies by default, step-up re-authentication for sensitive actions, no standing operator access to customer content, an append-only audit ledger, daily backups replicated to redundant storage, and malware scanning of uploads.
Independent assurance. A SOC 2 implementation programme, including third-party penetration testing, begins in November 2026. No SOC 2 report exists today and none is claimed. We will publish the position as it changes.
International transfers. Infrastructure is hosted in the United States. Standard Contractual Clauses are relied on where a transfer restriction applies.
Business, organisation and educational customers who need a Data Processing Agreement before it is published should contact privacy@ipguru.ai and we will provide the current draft for review.